Thomas Steenbergen, EPAM Systems | Open Source Summit Europe 2022
Thomas Steenbergen, head of the open source program office (OSPO) for EPAM Systems, explains why proactively managing open source software licenses and contributions is crucial.
Transcript
This is texturing TV. Hey guys, welcome back to the open source summit. We're back in Dublin, Ireland and we're talking with Thomas steenbergen who is head of the open source program office for epam systems.
They do a lot of work in digital transformation Engineering Services and just about anything else. You probably need or want them to do but we're gonna talk a little bit about what is it take to get involved in open source, and it's become an issue because there's a lot of people talking about how there's tons of people consuming open source. But maybe not giving back to the community and I don't think it's because their Spirit isn't willing.
I just don't think they have the mechanisms in place to do it. So from your perspective, what does it take to walk your way through all the business and compliance issues that an organization needs to deal with this to to engage with the open? Source Community.
What are you seeing? What are people overlooking? Yeah.
So I said like I have been helping organizations managing their open source and getting better at open source for for many years. And so yesterday I actually got exactly this question. So like hi.
I'm trying to convince my Executives to start on us Paul like to get really start properly managing open source, they already did. So yeah, that's the formula to do group and I'm on a steering committee member from the do group. We have a lot of materials out there which you can take as your your base template to do convincing, but for me what really helped and I said, I've been Consulting other people on that is we actually have tooling under the links relation called Oasis toolkit wage can basically it can you can Over old code repositories in your organization and it will figure out exactly what packet of what is what open source is pulled and find a package managers.
And so that's what I usually say. Like, hey, if you really use the material from the to-do group to see to get the base convincer and that the user standard NLF also has a lot of Auto materials in that but to hone it in to your relationship team. It should show like look actually we scanned all the code repulses already in our organization.
We are using already all of this and we actually have already a significant investment usually on product side already in open source, so but we're just consumers And what if we consumed the wrong thing? This is people would always misunderstand. There's some risk always with open source.
There's basically the licensing risk security risk that always come up but there's also the risk for instance that the community decides. Yeah that that open source Library. There's something better out there and they move on.
And so you might have built a multi-million product on something. But because you're not fluent in the ins and outs of Open Source, you bought you build it on the wrong. Open source and this has happened.
It happened in one of my previous employers. We built something nicely for machine learning. But unfortunately, they chose the wrong library to build it on.
So when it went to the customer the customers like yeah, that's very nice. But can you make it work with this other open source project? Because they were not.
Inactively evolved in this communities. So I would say like use the left material luciducah material to form your base material and then see how you can make it relatable to your sector. You should always have your open source strategy be connected to your business strategy.
So really see like where does open source add value? and and if you have that value means money and any executive will listen to Money don't go in with the cost saving aspects too much because most we see the shift in the so I love research just published research on that. The aspect of cost Savings of Open Source is going less and less but most companies.
Really? See more open source. as a strategic Tool for Enterprise transformation for instance.
You can use it for Innovation. You can use it to grow and maintain your top talent the developers you can use it for customer engagement. So it's a really another conversation and just focusing on cost.
It's a you can use it for much more more things, but you have to be smart about it. You have to know what you're doing and for that and open source program office or short on ospaul is the industry answer to basically manager open source. Didn't we just run into this with the log4j issue people discovered that oh my God.
This thing is being supported by, you know, a handful of people and they're kind of busy and this is not their full-time job. So when everybody was screaming for patches, they were like well get there as soon and as best as we can but it's you know, we're not getting paid for this so did people wake up then and realize just how dependent they are on a lot of small projects. I mean not everything is Linux right where there's a million people working on it and reviewing things.
Yeah. So again as a response of faisy look for Jay basically the inspiration acted and that's why we now have openness zeph, which I am also involved in I said the bit in openness that I work on is initiative is one of the 10 pillars is called as Mom everywhere. So I have been a long time contributor to spdx and I'm currently leading the spdx security profile where we're looking at.
How can you incorporate security information and as well, so for the people that are not familiar with it as well. So for a bit of materials think of it as Your ingredients list for your software. And so what you want but look for Jay what you want.
It does not just your own software stack, but it is also the software that you were buying in what you want. Ideally is you want to know for your own software for the software that you're acquiring you want to know. What are the ingredients?
And so if you know that you can basically do checks and you can actually see like, oh actually look for J. Is there. Do we clear like as volumes are not like the single solution the Silver Bullet solution, but they should part of the mix the more, you know about the open source that you're using.
The better you can amend your risk strategy how to deal with it as everything in business everything done. You have to there's always rewards and risks the same way with open source is then it's a strategic tool that you can use it. That's it has pros and it has cons, but I said if you Work together and what I always advocate in my way.
I always run my office program office the open source way. Because managing open source, you're dealing with it. There's no like one manual that I can give you.
I know it's like oh this is the the silver print for an Oxbow and this is exactly that. Every organization is different. So every open source program offense will be if there's some common bits and this is where I said a worker under the two group and together now to help all spouse.
So I recently together with Anna Jimenez from the she's the program manager from the group. We now started a new initiative called ospology life. And what it is is kind of a two-day workshop One Day presentation one day kind of unconference style that were organizing in Europe.
The first one is going to be at Ericson in Sweden, but we already are told have conversations to have one at aliander and Netherlands. We're an in Germany. We have two partners.
So the ideas basically locally in Europe work on half these recurring workshops every 1920 days in every country. That because it's local it's very approachable. Everybody can get a ticket to go to usage our own Twitter capital.
And so it's it's approachable. It's low cost but it's very in-depth. So we normally do this meeting under Chatham House Rules.
So you get this opportunity to just traveling in your own country, but meet people that you normally not be able to me. So the idea is there is normally at this kind of conference you get the managers like me. I'm here now.
what you want is you also got the engineers to the table and you want the Open source Engineers from One hospital talking to open source of another hospital and then you want to have them work together to tackle the problems together. So if I look for instance astrology life is for me. It's a continuation of a series we did in Germany under our open chain, which is the ISO standards for open source compliance.
and What we did is basically German car manufacturers. You have the same problem. We had European legislation.
It says you need to solve for develop material for your car. Just like, you know, what car parts are going to car software isn't sensible and other car parts so that collaboration started in Germany. And what happened?
This will just initial collaboration on tools and processes. And then we started what is called the opening reference group now and then it started the European the electric. I'm the the European chapter of the to do group.
So you see that once you bring people together, and they and they realize that basically the problems that they're facing on open source and their organization. Some of them are unique. but a lot of them are not let's collaborate.
So I said in Europe you have for instance phenos where you work together and the financial services work together, but for automotive side. That yeah, there was not something so then again open chain open chain automotive. And so really what people will need to do if for me is basically what I advise and advice from a lot of my clients basically if you do open source you as an author you have I do it the open source way.
Be part of the community contribute back. So when you advise your organization on officer's topics. You are familiar with that or if you don't know the answer.
I don't like I don't know all the answers are there open source is such a wine and complex field. But I do know that over the years. I've built of friends literally from Tokyo Japan to Seattle in the US and I know that I can pretty much get an answer a lot of topics and get multiple perspectives.
Within 10 to 15 minutes so that again that shows again the power of Open Source. So I'm said I'm advocating use the power of Open Source to solve your organization obvious challenges. So you get the maximum benefits out of it.
Do you think a lot of organizations are also getting hung up on the licensing terms? Because not everything is the same there is not one say master license that gets applied to every project they all have slightly different variations and that becomes part of the conversation as well. Yeah, so that's what I typically see when an organization start managing open source.
The first thing it comes a legal thing. And this is also in the to-do group. We have a maturity model.
The first one is really very look at the legal aspects and degradation. And so what we have been doing again the same group, so it's it's borsche Porsche here Technologies and epam also and also BMW working together to say like hang on. This is a common problem.
instead of us Basically, all figuring is out ourselves. Why don't we build a solution for it? We didn't like what we could get from the commercial vendors.
So we said like let's build our own. so then we created a tool called Always attribute toolkit that basically makes it easier does high compliance in your size of the pipeline, but you can make it with multiple compliance level. It's really Yeah, it originally started out as a license compliance tool.
But now I think it more it's like an open source policy automation tool. and the film therefore that is it's a fully open source. I'm not only giving away the tool.
We're also giving away the data remember licensing all the conflict. We're giving the data my Hospital gives the data away, but we are doing during our clearance. We just open source as well.
And we're also giving you reference policies. So for a new auspower to start out instead of them getting hang up and try everything else. Where I want them to go eventually.
Oh, hang on I can just reuse what these other ausposts have already built and I can use it as my Foundation. And then I can build on top of that and I can contribute back and that makes hopefully the topic of compliance. A less of a burden and then they can really start focusing.
Okay, because we now have this compliance some more tackled. Now, let's focus on contributing back. Let's focus on how we are good citizens in the community and make things sustainable.
In those contributions back. I mean there's a lot of obsession about contributing code and all that other stuff and that's great. But those contributions can also be reviews of code.
They can be documentation. They can be heck they can even be money. Right?
So the question is do organizations understand that there's other ways to give back besides just having you know, people contribute code and working on a particular project. There's a there's a lot of there's a big need here. Yeah, so the fun thing and you always see it and there's a lot of people always asking like, why are these big corporations not contributing back?
a fun fact a lot of them actually are but for they're just investing in different areas, so again Most large corporations that we work with and that I've worked out years. They don't use like a few open source libraries. No, they use tens if not hundreds of thousands.
So the real question comes Okay, we have we have some money set up aside for sponsoring for forgiving back or even engineering time. Where are we going to put it in? So the usual way you can go use the foundation you can use something like tight lift that automatic Donuts, but for me where I'm looking at where I'm now working on the on the solution for the tooling that we develop is, how can I really look at my stack get the information since we're anyways, this is the funny thing where anyways analyzing the stack for licensed compliance for security.
So we have all of this data already on what opens packages we're using now, how can we do the next step? that we can look like okay, which of those projects need funding and right and there is no standard for that yet. So Julia had a reading from from Cisco.
She had a really nice talk on that this morning. Unlike how there's so many expectations from from basically consumers of software towards the officers projects, but those are often misaligned. And wouldn't it be nice if we have some kind of standard where we could figure out for what you use do they want money?
Do they want engineering power or simply said that really funny? Sometimes office projects they don't want any money if I have had as well. I'm an open source maintainer if you give me money, I have to figure out okay.
How does this work my taxes? How is I I rather have a most cases that people contribute codes or the polite way is to set the first thing that any company can do just give a qualified. Thank you say like we as company we use this piece of Open Source.
We're grateful for these guys doing that's that's it's literally cost. Nothing far from maybe your marketing team. Start there.
Or you may sponsor a Meetup, right? Oh, you said that's what we're now doing with with those policy life that some companies have some inexperience companies that are not familiar with open source coming up and it's like, oh we want to get started. That's like well Just give me a room for 40 people and I will bring very Experience open source people and less experience people together.
And that's how you can learn again. It's a simple as just opening a door reaching out to the right people and US Open Source people. We're generally very very friendly and open about collaborating.
Do you think we'll see a time when multiple companies will share a same open source office or program or something where they're going to collaborate together? So that's or actually already happening on the two, but is it? It's a broad topic.
So what's now what's happening? This is maybe really confusing because people always like oh my getting a friend or get everything in the book. So the bigger picture think of as the do group as the overall umbrella for open source Management in their organization, but then if you look for instance to say a compliance program, there's the open chain Community there.
This is the ISO standards ISO 5230. What is really nice to standard for for how should you set your compliance program? Then you have spdx your Soulful villain material.
If you want to exchange between organization or even within your organizations, then we have chaos if you want to look at like metrics so our community health for instance or other things and It can also it's sometimes weird and then we have again Finos for specifically if you're in the financial services industry. So this might look confusing and that's where we used to do try to help as an act as a guide to basically say like hey. Yeah, it might sound a little confusing.
There's all this good group, but that's problem. The challenge again open source is very broad. But under our left and I don't know also with collaborations with the eclipse foundation and always I there is basically a framework being developed now where we kind of like, okay you want to do this topic here is the community to interact we can make all the introductions you want to do that topic go there and it's slowly coming together making it easier understand about it's still a set.
There's not one. Manual one way to do open source, every organization is different. And there's no Silver Bullet but to get we as the community are very open and are willing to show you.
What is your challenge? If that's probably the community right that's right for you. One of the things we hear about is that there's a lot of work being done on S bombs and the question becomes, you know, so I collect all this data.
I put it in this document and I give it to somebody and then what happens I mean, how does this thing evolve? How does that become actionable? It's nice to have a list of ingredients.
But am I engaging back through the SBOM with the people who send it to me in some way. I mean, what is the ultimate outcome of having all this? Yeah, so the world of Xbox is still developing and a lot of people ask me like hey, what are some real-worlds applications of as-bombs?
So they're already happening. So if I look for instance in the German automotive industry, they're working on this concept called false portals. And the ideas basically they're that now when they do reporting so you have a say Have A supplier offender for finding software to a car manufacturer.
Now this can literally be still paper literally favor and Pen most tired or Excel sheets. And I wanted to go to something machine readable. So they say like Hey, we're gonna adopt spdx, but then you have an spdx file.
How do you get it to? The car manufacturers and then it's like oh we're gonna build a fast portal which is kind of a rest API. And what it can do is the vendor can automatically upload to the false portal.
They already get automatically feedback back is a thumbs up. Is it is it thumbs down so they know they know early off. It's a software that the developing is complying with the contracts and that if you now look and as I have worked in this world the open source like requirements this can be as this used to be.
Well most companies still have that it can go up to 20 Pages what you now see through the development of having the links Foundation because we now have an ISO standard Scania for instance made that paragraph. It's now like a simple paragraph. So it's much more simplified and it just space it says what you want you to be open chain performance.
And we want you to provide us and as form in spdx. then in return our tooling will tell you where your thumbs up our thumbs down so you can during the development of the software already know. Are we good to go?
Yes, or no instead of the traditional way where the software usually gets developed and just for release it just gets checked and then usually there's like maybe a one week or two weeks remediation fee and then the vendors are all sweating like, oh there's a problem. I have one week to fix it. You just so we're going to a more.
Integrated digitalized supply chain. This makes everything more efficient and just that efficiency alone. Save so many hour wasted hours.
Of course that is just again, it's just phase one. First off there's so many other things that we what we can do afterwards. So I already used as bombs to because again, I know and already what is being used.
To optimize my engineering. Organization I look at like hey, these guys are all using the same open source project, but they're using a slightly different version. That means we have multiple compliance cost because we have to again we have to do a license clearing security.
There's for all these different versions, but then we have to also the reporting what if we stand arise is what if we simplify our stack whatever smarter about and that's basically where yeah, most also start with compliance and then I say like, yeah, but you also need to look. At what's causes? If you consume if you're not smart in your consumption of Open Source, you have lots of compliance problems.
How can you better at the consumption of Open Source? Well, you need to be part of the community, how can you be part of the community? Well start contributing.
So you see it's always like it's a side until you really need to work on all of those four things in the same time, and that's that's a lot of change but that's it. I said form an ospo. It's the best solution.
Those people were able to advise you how to do this how to contribute back how to do your compliance and not just make this a legal topic was compliance is much more than legal. It's a technical and business topic. They're always choices need to be made.
All right, guys, you heard it here. This is how you create a virtuous cycle in the open source community so that new business can participate Thomas Thanks me on the show. You're welcome.
All right guys, we'll be back again in a couple of minutes.





